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Abstract 

In this paper, a photon-number-resolving decoy state quantum key distribution scheme is pre- 
sented based on recent experimental advancements. A new upper bound on the fraction of counts 
caused by multiphoton pulses is given. This upper bound is independent of intensity of the decoy 
source, so that both the signal pulses and the decoy pulses can be used to generate the raw key 
after verified the security of the communication. This upper bound is also the lower bound on the 
fraction of counts caused by multiphoton pulses as long as faint coherent sources and high lossy 
channels are used. We show that Eve's coherent multiphoton pulse (CMP) attack is more efficient 
than symmetric individual (SI) attack when quantum bit error rate is small, so that CMP attack 
should be considered to ensure the security of the final key. finally optimal intensity of laser source 
is presented which provides 23.9 km increase in the transmission distance. 



I. INTRODUCTION 



Quantum key distribution (QKD) is a physically secure method, by which private key 
can be created between two partners, Alice and Bob, who share a quantum channel and a 
public authenticated channel [1]. The key bits then be used to implement a classical private 
key cryptosystem, or more precisely called one — time pad algorithm, to enable the partners 
to communicate securely. The best known QKD is the BB84 protocol published by Bennett 
and Brassward in 1984 [2], security of which has been studied deeply [3-7]. 

Experimental BB84 QKD was demonstrated by many groups [8]. An optical BB84 QKD 
system includes the photon sources, quantum channels, single-photon detectors, and quan- 
tum random-number generators. In principle, optical quantum cryptography is based on 
the use of single-photon Fock states. However, perfect single-photon sources are difficult to 
realize experimentally. Practical implementations rely on weak laser pulses in which photon 
number distribution obeys Possionian statistics. Thus, no-cloning principle is ineffective in 
the case of multiphoton pulses. If the quantum channel is high lossy, Eve can obtain full 
information of the final key by using photon number splitting (PNS) attack without being 
detected [9-13]. In GLLP [7], it has been shown that the secure final key of BB84 protocol 
can be extracted from sifted key at the asymptotic rate 

R = (1 - A) - H 2 (e) - H 2 (e + A), (1) 

where e is the quantum bit error rate (QBER) found in the verification test and A is the 
fraction of counts caused by multiphoton pulses. This means that both the QBER e and 
the fraction of tagged signals A are important to generate the secure final key. It has been 
shown that Eve's PNS attack will be limited when Alice and Bob use the decoy-state pro- 
tocols [14-20] or the nonorthogonal states scheme [21]. In the decoy-state protocols [14-20], 
an important assumption is that the detection apparatus cannot resolve the photon num- 
ber of arriving signals. Recently, some photon-number-resolving detection apparatus were 
presented [22-24], especially the noise- free high-efficiency photon-number-resolving detectors 
[24]. Thus, a lower upper bound on the fraction of counts A is desired with the photon- 
number-resolving detectors. As a matter of fact, Eve's some other attacks, such as coherent 
multiphoton pulse (CMP) attack, should also be considered or else security of the final key 
will be unreliable. 
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In this paper, we present a photon-number-resolving decoy state (PDS) quantum key 
distribution scheme based on recent experimental advancements. We show that the upper 
bound on fraction of counts caused by multiphoton pulses is //, no matter how high the 
channel loss is. We show that coherent multiphoton pulse (CMP) attack is more efficient 
than symmetric individual (SI) attack. We present the optimal approach to generate the 
sifted key from the raw key. Optimal parameter of intensity of laser source is presented to 
generate the secure final key. This paper is organized as follow: We first introduce our PDS 
QKD scheme. Then we discuss Eve's CMP attack. Next, we present the optimal approach 
to generate the sifted key from the raw key. Then we discuss how to select optimal intensity 
of laser source to generate the secure final key. Finally, we discuss and conclude. 

II. PHOTON-NUMBER- RESOLVING DECOY STATE QUANTUM KEY DISTRI- 
BUTION 

At present, practical "single-photon" sources rely on weak laser pulses in which photon 
number distribution obeys Possionian statistics. Most often, Alice sends to Bob a weak laser 
pulse in which she has encoded her bit. Each pulse is a priori in a coherent state \^/Jle ie ) of 
weak intensity. Since Eve and Bob have no information on 9, the state reduces to a mixed 
state p = J 7^\^fjie l6 )( x ^fjie ie \ outside Alice's laboratory. This state is equivalent to the 
mixture of Fock state J2 n p n \n)(n\, with the number n of photons distributed as Possionian 
statistics p n = p^[n] = p n e~^ jn\. The source that emits pulses in coherent states \^JJie ie ) 
is equivalent to the representation as below: With probability p , Alice does nothing; With 
probability p n (n > 0), Alice encodes her bit in n photons. In order to gain Alice's encoding 
information, Eve first performs a nondemolition measurement to gain the photon number of 
the laser pulses. When she finds there is only one photon in the pulses, she may implement 
symmetric individual (SI) attack on this qubit [12]. Otherwise, if there are two or more 
than two photons in the pulses, she may implement PNS attack on Alice's qubit. In long 
distance QKD, the channel transmittance rj can be rather small. If rj < (1 — — fie~^)/ fi, 
Eve can gain full information of Bob's final key by using the PNS attack [11]. 

In order to detect Eve's PNS attack, Alice can introduce a decoy source // to ensure the 
security of their QKD. Since Bob's detection apparatus is sensitive to the photon number, 
in the absence of Eve, photon number distributions in Bob's detectors are also Poissonian 
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(Here, we assume that the dark counts rate r^ark in Bob's detectors is zero. We will discuss 
the realistic condition of that r^ark > later.), 



n 



P l s%>] = ^-e^\ (2) 



TV. 



P l d °: c >] = (3) 

Without the decoy state, the necessary condition of that Eve can implement her PNS attack 
without being detected is [11] 

n— 1 oo 

p sig [n](l -Y^fM) + E Psi 9 \J]fU,n) > P l s % s H (4) 

i=0 j=n+l 

where /(to, k) is the probability of that Eve forwards k photons to Bob and stores the other 
m — k photons. In general, let us assume Eve implements PNS attack P n on Alice's pulses. 
Consider the case of that decoy states are used by Alice. Essentially, the idea of decoy-state 
is that [17] 

P n (signal) = P n (decoy) = P n (5) 
e n (signal) = e n (decoy) = e n . (6) 

In this case, Eve can implement her PNS attack without being detected if and only if that 

n— 1 oo 

Psi 9 m + E PsioWihn) =tf£[n], (7) 

i=0 j=n+l 
n—1 oo 

Pdec [n](l - fin, E PdecWih n) = PdecH (8) 

i=0 j=n+l 

Using the Taylor series, we can obtain that 



f{n 1 i) = \^j V i (l- V ) n -\ (9) 

f(j,n) = Q»7 B (1 - V) j ~ n - (10) 

Experimentally, these solutions just correspond to the case of that Eve blocks every photon 
with the probability 1 — 77, i.e., Eve forwards every photon with probability i] through her 
lossless channel (This can be realized by using a beam splitter with the reflection probability 
1 — 1] and the transmission probability rj.). We will calculate the amount of information Eve 
can gain by using her PNS attack described by the equations (7) and (8) later. 



III. COHERENT MULTIPHOTON PULSE ATTACK 

From Eq.(l) we know that the rate of the secure final key is not only determined by 
the tagged counts but also determined by the QBER. That is, Eve may use some other 
eavesdropping schemes on the multiphoton pulses besides the PNS attack. Of course, these 
attacks will cause some QBER which could be detected in the verification test. A general 
attack scheme Eve may use is coherent multiphoton pulses attack. Let us first review the 
SI attack to introduce the CMP attack. When a photon propagates from Alice to Bob, Eve 
can let a system of her choice, called a probe, interact with the photon. Eve can freely 
choose probe and the initial state. But her interaction must obey the laws of quantum 
mechanics. That is, her interaction must be described by a unitary operator. After the 
interaction, Eve forwards the photon to Bob. Eve will perform a measurement on her probe 
to draw Alice's encoding information after Alice announces the basis she used. This is Eve's 
SI attack scheme. In the case of a multiphoton pulse, Eve will let her probes to interact 
with Alice's photons one-to-one. After Alice's announcements, Eve will perform a coherent 
measurement on her probes. We call this attack as CMP attack. Obviously, the simplest 
CMP attack is SI attack: If Alice sends a photon in the state | j), the result may be written 
as 

u(\ T>|o» - \x), (li) 

where \X) is the entangled state of the probe and the photon [25]. Likewise, we can obtain 
the state \Y), \U) and \V) corresponding | |), | — >) and | <— ), respectively. In SI attack 
scheme, one can obtain that \X) = V7| T)IH + v^l DIH \ Y ) = v 7 /! l)\<f>l) + v^l Wl), 
W) = y/J\ ->)|^> + V^l HIM and 1*0 = V 7 /! Hl</H + v^l HIM, where / is 
the fidelity of the state and f + e = 1. From the unitarity of the interaction, we have 
that (<pi\9i) = ((pi\0i) = (</>tIH = (01 1 6 *?) = °- lt then follows from (0 T |H = cos a that 
QBER=[1 — cosa]/2. The maximal information Eve can gain is that 

,„ _ i _ ft( i±^HZ), (12, 

where h(x) = — xlog 2 x — (1 — x) log 2 (l — x) and e is QBER. 

In Eve's CMP attack scheme, she attaches her probes with all photons in the multiphoton 
pulse one-to-one. She interacts the probe-photon pair unitarily and then forwards the pulse 
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= E #^l^) 0n -^T)^((0Tl)^((^l) 0i (16) 



to Bob. She measures the probes coherently after Alice's announcements. This can be 
described as 

p(\ r>io»r -> \x)-i (13) 

where [U(\ T)|0))]® n = U(\ 1)\0)). . .U(\ t)|0)) , and |X)® n = \X). \X) . Likewise, one can 

n n 

obtain \Y)® n , \U)® n and \V)® n . Suppose Alice announces that | |), | |) basis has been used. 
It has that 

\X)*"=(y/f\V\<h)+y/E\l)\0i))*", (14) 

i^) 0n = (v / 7ii)i0i) + v^ir)i^)r- (is) 

Then the two density operators that Eve must distinguish are 

n!/ n -V 
(n — 

pi = E #^i^) 0n "i^)^((^i) 0n " l ((^i) 01 (17) 

i=0 ^ 

The optimal information Eve can gain from these two states can be obtained as follow: 
Eve first performs the measurements on her probes. If her measurement results are that 
1^)®""%)®* (or 1^)®""%)®*), where 1 < % < n - 1, then Eve know that her density op- 
erator is p| (or pi) since = = (0tl^l) = (04. 1 ^t) = 0- Only if the measurement 
results are |0f)® n , |^)® n , |0j.)® n , and |0j.)® n , can Eve not distinguish her density operators. 
Suppose that Eve's measurement result is |0t)® n . From (4>i\4>i) = cos a, we can obtain that 

m^)r n = cos n a. (18) 

The maximal probability that Eve can distinguish pj from pi correctly is that 1+v/1 ~ cos2 — . 
Thus, the maximal information Eve can gain is that 



i=0 
n 



1 + y/1 - cos 2n a.. n/1 ,,l + \/l _r 



cos 2n a 



W(n) = (1-/"- e") + f (1 - M o )) + ~ K )) 



= 1 _ (r + e>( i±^il^!)!! ) . (19) 

That is, when Eve uses the CMP attack scheme, optimal information she can gain is I C Mp( n )- 
Suppose Eve interacts with n photons. If these n photons are from n independent qubits 
(Qubits are uncorrected since weak coherent sources are used.), then information Eve can 
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gain is nisi- If these n photons are from a multiphoton pulse, then information Eve can 
gain is IcMp(n). When the QBER is small and the photon number n is not so big, we can 
gain that IcMpij 1 ) > nisi, see Fig.l. In fact, most of the multiphoton pulses are two-photon 
pulses since weak coherent sources are used experimentally. Numerical solution shows that 
^cmp(2) > 2/5/ if e < 0.11, at which error correction can be implemented. That is, CMP 
attack is more efficient than SI attack when weak coherent sources are used [26]. 

IV. FROM RAW KEY TO SIFTED KEY 

From discussion above, we know that Eve can get more benefits from a multiphoton 
pulse than that from the single-photon pulse. Since Bob's detection apparatus can resolve 
the photon number of an arriving pulse, Alice and Bob can discard all of the multiphoton 
pulses out of the raw key to generate the sifted key. Therefore, only the pulses detected in 
Bob's detectors as the single photon pulses will be used to generate the sifted key. In this 
case, the fraction of counts caused by multiphoton pulses in the sifted key is that 

A = En=2 /x ra e~^(l - r]) n - l n/n\ 
X^°=i yU n e~^(l — r\) n ~ x njn\ 

= l-e"^ 1 ""), (20) 

where 

limA = l-e^. (21) 

That is, the upper bound on the fraction of count caused by multiphoton pulses is A = 
1 — e~ M with high losses. This upper bound is approximate to /x when faint coherent sources 
are used. In order to gain the secure final key, a fraction H 2 (e) of the sifted key bits are 
sacrificed asymptotically to perform error correction and a fraction H 2 (e + A ) of the sifted 
key bits are sacrificed to perform privacy amplification [27]. After the correcting errors in 
the sifted key, Alice and Bob can execute privacy amplification in two different strings, the 
sifted key bits arising from the untagged qubits and the sifted key bits arising from the 
tagged qubits. The worst case assumption is that the bit error rate is zero for tagged qubits 
[7]. Therefore, secure final key can be extracted from sifted key at the asymptotic rate 

R > (1 - A ) - H 2 (e) - (1 - A )H 2 (—^—). (22) 

1 — An 
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In the prior art GLLP [7], A = p mu iu/n, where p mu iu is the probability of Alice's emitting a 
multiphoton signal. This is the worst situation where all the multiphoton pulses mitted by 
Alice will be received by Bob. In our scheme, only "single photon" pulses detected in Bob's 
detectors are used to generate the sifted key. If this "single photon" pulse is a multiphoton 
pulse emitted from Alice, then we assume that it belongs to the tagged qubits. The other 
"single photon" pulses detected in Bob's detectors are real single photon pulses emitted from 
Alice. Thus, Eve's CMP attack can be ignored in our scheme. 

V. PDS QKD WITH IMPERFECT PHOTON-NUMBER-RESOLVING DETEC- 
TORS 

Resolving power of realistic photon-number-resolving detectors is finite. Suppose photon 
number resolving power of the detectors is n . Let us assume that Eve can attack the photon 
pulses using PNS attack freely when the number of a pulses is bigger than n . In this case, 
additional information Eve can gain is that 

E~ i^-^(i-^-V(^-i)!' 1 ] 

Typically, n = 4, n = 10~ 3 , /i — 0.1. Then we can estimate that A' < 10 -3 , which is a very 
small quantity. The particular resolving power of detectors used in Ref.[24] can go up to 10 
photons or so (~8 eV), so that the quantity A' <C 10~ 10 , which is negligible. In fact, Eve 
can not get benefit from the pulses n > n since all of the multiphoton pulses detected in 
Bob's detectors are discarded, i.e., A' = 0. 

Another question is dark counts from blackbody photons propagating through the optical 
fiber. Fortunately, these photons can be filtered well. Experimentally, a really good filter 
(40 dB out-of-band rejection, lOnm wide passband), would result in 0.05 Hz of background 
counts [28]. Suppose the pulse rate emitted from Alice is r pu i and the dark count rate is 
rdark Hz. We can obtain the normalized dark count rate d (dark counts per pulse) in Bob's 
detectors is that d ~ Vdark . Distribution of dark counts in Bob's detectors is that 

rpuim 

Pdark[n]=d n . (24) 

Therefore, in experiment, Bob can obtain photon number distribution of the laser pulse by 
subtracting the dark counts from the real counts. QBER e^rfc caused by dark counts should 
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be considered, especially in the long distance QKD, 

6 Co "I - ddark i 

where tdark = d/2, and e is caused by the imperfections of the optical setup [1]. 



(25) 



VI. OPTIMAL INTENSITY OF LASER SOURCE TO GENERATE SECURE FI- 
NAL KEY 

In BB84, the rate of generating raw key is approximate to \nr\. Thus, the rate of gener- 
ating secure final key is approximate to — A )rjR. That is, the rate of generating the 
secure final key is approximate to Rf, where 

R f = ^(1 - AoM(l - A - H 2 (e) - (1 - A )// 2 ( r ^-)], (26) 

where A = 1 — e~ M . In practice, e and n are constants when the transmission distance is 
constant. Therefore, the only variable in Rf is fi. Rf reaches its maximum at the point 
= 0. In this way, we can obtain optimal parameter /z, see Fig. 2. 

VII. DISCUSSION AND CONCLUSION 

In the prior decoy state QKD [14,15,17], it requires that /i' > /i. In [14,15], the upper 
bound on the fraction of counts caused by the multiphoton is A < Only if [i — // 

can the upper bound be reduced to // [15]. In our scheme, \x is independent of // so that 
both signal pulse and decoy pulses can be used to generate the raw key. Another difference 
is that all the pulses detected in Bob's detectors are discarded in our scheme, so that Eve's 
CMP attack does not exist in our scheme. However, CMP attack should be considered in 
[14,15,17] to ensure the security of the final key. 

In our scheme, from A = 1 — e^ 1- ^, we can conclude that the upper bound A = 1 — 
can not be reduced any longer as long as weak coherent sources and high lossy channel are 
used, so that the quantity A = 1 — e^^ is also the lower bound on the fraction of counts 
caused by the multiphoton pulses. Thus, the fraction A = 1 — seems "inherent" in the 
long distance QKD with weak coherent sources and high lossy channel. 

In summary, we have discussed the security of practical BB84 QKD protocol with weak 
coherent sources, noises and high losses. We have presented a PDS QKD scheme based 
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on recent experimental advancements. The upper bound on fraction of counts caused by 
multiphoton pulses is independent of the intensity of decoy source so that both the signal 
pulses and decoy pulses can be implemented to generate the raw key after verified the 
security of the QKD. We have shown that CMP attack is more efficient than SI attack. 
Finally optimal \i is presented to improve the rate of generating the secure final key. 
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X. CAPTION 

Caption 1. (Color online.) Information vs photon number. Information Eve can gain 
from n photons by using SI attack (a) is nisi since these n photons come from n uncorrelated 
photon pulses. If these n photons are from a multiphoton pulse, then information Eve can 
gain is IcMp(n) (b). Numerical solution shows that Icmp(2) > 2/5/ when e < 11%. And 
Icmp{3) > 3/5/ when e < 6.8%. CMP attack is more efficient than SI attack since weak 
coherent sources are used experimentally. 

Caption 2. (Color online.) Rate of generating final key vs transmission distance. In 
order to be comparable, we use the parameters in [17,29] instead of [24]. When \x = 0.1, 
transmission distance is close to 140.2 km which is comparable with LMC in [17]. Numerical 
solution shows that optimal intensity of laser source is \x ~ 0.7 (transmission distance over 
164.1 km). That is, optimal intensity of laser source provides 23.9 km increase in the 
transmission distance. Transmission distance is stable to small perturbations to the optimal 
/i (up to 20% change of //, less than 0.3% change of transmission distance). Here, we have 
verified that error correction are allowable for the maximal transmission distance. 
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